CVE-2013-7225

EUVD-2022-3374
Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
fatfreecrmfat_free_crm
𝑥
≤ 0.12.0
fatfreecrmfat_free_crm
0.9.6
fatfreecrmfat_free_crm
0.9.7
fatfreecrmfat_free_crm
0.9.8
fatfreecrmfat_free_crm
0.9.9
fatfreecrmfat_free_crm
0.9.10
fatfreecrmfat_free_crm
0.10.1
fatfreecrmfat_free_crm
0.11.0
fatfreecrmfat_free_crm
0.11.1
fatfreecrmfat_free_crm
0.11.2
𝑥
= Vulnerable software versions